Jenkins Update
3133Warning Date
Severity Level
Warning Number
Target Sector
24 December, 2019
● Medium
2019-760
All
Description:
Jenkins has released an update to address multiple vulnerabilities in the following system versions:
- Alauda DevOps Pipeline Plugin
- Weibo Plugin
- Build Failure Analyzer Plugin
- buildgraph-view Plugin
- Gerrit Trigger Plugin
- Mantis Plugin
- Maven Release Plug-in Plugin
- Mission Control Plugin
- Pipeline Aggregator View Plugin
- RapidDeploy Plugin
- Redgate SQL Change Automation Plugin
- Rundeck Plugin
- SCTMExecutor Plugin
- Spira Importer Plugin
- Team Concert Plugin
- WebSphere Deployer Plugin
- Alauda Kubernetes Suport Plugin
Threats:
An attacker could exploit these vulnerabilities by doing the following:
- Man-in-the-Middle
- Cross-Site Scripting
- Cross-site request forgery (CSRF)
- Obtain Sensitive information
Best practice and Recommendations:
The CERT team encourages to update the affected versions according to the links below: